# Logstash is affected by Apache Log4j2 2.17.0 Vulnerability CVE-2021-44832?

**URL:** https://discuss.elastic.co/t/logstash-is-affected-by-apache-log4j2-2-17-0-vulnerability-cve-2021-44832/293162
**Category:** Logstash
**Created:** [December 30, 2021, 1:51am UTC](https://discuss.elastic.co/t/logstash-is-affected-by-apache-log4j2-2-17-0-vulnerability-cve-2021-44832/293162 "2021-12-30T01:51:17Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)
#### Post date: [January 2, 2022, 12:50am UTC](https://discuss.elastic.co/t/logstash-is-affected-by-apache-log4j2-2-17-0-vulnerability-cve-2021-44832/293162/2 "2022-01-02T00:50:56Z")

</div>

We will update the [official advisory](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476).

Sidenote: This security issue has a very strong precondition — attackers need to be able to change the logging configuration. Generally that means already being admin on the system.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-is-affected-by-apache-log4j2-2-17-0-vulnerability-cve-2021-44832/293162)._
